Google and GitHub OAuth complete successfully, but the callback is blocked by Cloudflare.
I performed extensive diagnostics:
✓ DNS works
✓ Routing works
✓ Google and Cloudflare work normally
✓ OAuth works correctly
✓ api.zoo.dev returns 403 from Cloudflare
✓ Download server is also blocked
I tested from:
Windows PC
Android phone
Home Internet (Kyivstar)
Mobile Internet (Kyivstar)
The result is identical.
After connecting through Proton VPN everything works immediately.
Cloudflare Ray IDs:
a1f2ea32fb145b75
a1f2f14d7b305e99
a1f2fbc98a7d8e64
Could you please check your Cloudflare WAF / Firewall rules?
It appears that requests from my network are being blocked before reaching your backend.
Unfortunately, Cloudflare only allows us to block full countries and because of US sanctions against Russia, we can’t selectively block only the occupied portions of Ukraine. We’re hoping the situation improves and will continue to revisit this in the future.
This IP belongs to the network of Kyivstar, a Ukrainian internet provider. I am not accessing Zoo from Russia.
The service works correctly when I connect through a European VPN, which strongly suggests that the original Ukrainian IP address is being incorrectly classified or blocked by the geolocation rule.
Could you please:
Confirm what country and region Cloudflare assigns to IP 176.8.12.189.
Check why this Ukrainian Kyivstar IP is being treated as a sanctioned location.
Review the Cloudflare Ray ID previously provided:
a1f2fbc98a7d8e64
Escalate this case to your technical or security team.
Consider allowing this IP or correcting its geolocation classification.
My actual location is: Rivne, Ukraine.
I am not requesting access from Russia or from an occupied territory. I am asking you to investigate an apparent IP geolocation or filtering error affecting a Ukrainian ISP address.
Please let me know if you need a screenshot, timestamp, traceroute, or additional connection details.
We have all of Ukraine blocked by our policy. We would like to selectively block only occupied portions, but don’t currently have the fine-grained controls to do that. Really sorry about that and hope that we have more options in the future.